Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8fww-64wc-46pf

Опубликовано: 21 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud, Ultimate and Ultimate MT editions are affected, as other editions do not expose relay endpoints.

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud, Ultimate and Ultimate MT editions are affected, as other editions do not expose relay endpoints.

EPSS

Процентиль: 19%
0.00269
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-306

Связанные уязвимости

nvd
2 дня назад

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud, Ultimate and Ultimate MT editions are affected, as other editions do not expose relay endpoints.

debian
2 дня назад

Improper authentication in the agent receiver of Checkmk <2.5.0p10 all ...

EPSS

Процентиль: 19%
0.00269
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-306